<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA 9.12 how to remove an ACL line in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-9-12-how-to-remove-an-acl-line/m-p/5047242#M1110240</link>
    <description>&lt;P&gt;Hi MHM, thanks for your reply. "inactive" didnt make a difference and a reboot unfortunately isn't an option in this environment. However, as suggested in the below response, entering the full "no access-list ...." command blindly works.&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;</description>
    <pubDate>Thu, 21 Mar 2024 22:41:58 GMT</pubDate>
    <dc:creator>ivanDmi</dc:creator>
    <dc:date>2024-03-21T22:41:58Z</dc:date>
    <item>
      <title>ASA 9.12 how to remove an ACL line</title>
      <link>https://community.cisco.com/t5/network-security/asa-9-12-how-to-remove-an-acl-line/m-p/5046039#M1110180</link>
      <description>&lt;P&gt;Hi All&amp;nbsp;&lt;/P&gt;&lt;P&gt;Have just come across an odd problem. Need to remove couple of lines from an existing ACL, however, there seem to be a limitation of some sort as there's no option to specify the ACL name, this is ASA 9.12 (same on 9.14, 9.16):&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;(config)# no access-list ?&lt;/P&gt;&lt;P&gt;configure mode commands/options:&lt;BR /&gt;&amp;nbsp; alert-interval&amp;nbsp; Specify the alert interval for generating syslog message&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 106001 which alerts that the system has reached a deny flow&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; maximum. If not specified, the default value is 300 sec&lt;BR /&gt;&amp;nbsp; deny-flow-max&amp;nbsp;&amp;nbsp; Specify the maximum number of concurrent deny flows that can&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; be created. If not specified, the default value is 4096&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;At the same time, a 9.0 ASA works as expected:&lt;/P&gt;&lt;P&gt;(config)# no access-list ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;configure mode commands/options:&lt;BR /&gt;&lt;STRONG&gt;&amp;nbsp; WORD &amp;lt; 241 char&amp;nbsp; Access list identifier&lt;/STRONG&gt;&lt;BR /&gt;&amp;nbsp; alert-interval&amp;nbsp;&amp;nbsp; Specify the alert interval for generating syslog message&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 106001 which alerts that the system has reached a deny flow&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; maximum. If not specified, the default value is 300 sec&lt;BR /&gt;&amp;nbsp; deny-flow-max&amp;nbsp;&amp;nbsp;&amp;nbsp; Specify the maximum number of concurrent deny flows that can&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; be created. If not specified, the default value is 4096&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There seem to be no differences in AAA config, I access both ASA with privilege level 15.&lt;/P&gt;&lt;P&gt;To make things even more complicated, I can modify ACLs via ASDM and with "preview commands" option selected, the ASDM seem to generate lines exactly as expected, i.e. "no access-list TEST-ACL extended permit tcp any any eq https"&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Thu, 21 Mar 2024 03:24:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-9-12-how-to-remove-an-acl-line/m-p/5046039#M1110180</guid>
      <dc:creator>ivanDmi</dc:creator>
      <dc:date>2024-03-21T03:24:10Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 9.12 how to remove an ACL line</title>
      <link>https://community.cisco.com/t5/network-security/asa-9-12-how-to-remove-an-acl-line/m-p/5046045#M1110181</link>
      <description>&lt;P&gt;Try use inactive first then remove the ACL line&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Thu, 21 Mar 2024 04:13:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-9-12-how-to-remove-an-acl-line/m-p/5046045#M1110181</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-03-21T04:13:21Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 9.12 how to remove an ACL line</title>
      <link>https://community.cisco.com/t5/network-security/asa-9-12-how-to-remove-an-acl-line/m-p/5046714#M1110215</link>
      <description>&lt;P&gt;Did you actually try to type in the whole command even if it's weirdly not showing you the access list option? based on Cisco doc it should still work in the same way on 9.12:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/asa/asa912/configuration/firewall/asa-912-firewall-config/access-acls.html" target="_blank"&gt;CLI Book 2: Cisco ASA Series Firewall CLI Configuration Guide, 9.12 - Access Control Lists [Cisco ASA 5500-X Series Firewalls] - Cisco&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 21 Mar 2024 14:02:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-9-12-how-to-remove-an-acl-line/m-p/5046714#M1110215</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2024-03-21T14:02:32Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 9.12 how to remove an ACL line</title>
      <link>https://community.cisco.com/t5/network-security/asa-9-12-how-to-remove-an-acl-line/m-p/5046728#M1110220</link>
      <description>&lt;P&gt;I check in my lab with and without inactive the NAME of ACL must appear&amp;nbsp;&lt;BR /&gt;so try reboot the ASA and check again or use inactive only without remove ACL&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Thu, 21 Mar 2024 14:11:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-9-12-how-to-remove-an-acl-line/m-p/5046728#M1110220</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-03-21T14:11:27Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 9.12 how to remove an ACL line</title>
      <link>https://community.cisco.com/t5/network-security/asa-9-12-how-to-remove-an-acl-line/m-p/5047122#M1110235</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;Try&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;show run access-list&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;And see what you actually have on the device.&lt;/P&gt;
&lt;P&gt;HTH,&lt;/P&gt;
&lt;P&gt;-A&lt;/P&gt;</description>
      <pubDate>Thu, 21 Mar 2024 19:52:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-9-12-how-to-remove-an-acl-line/m-p/5047122#M1110235</guid>
      <dc:creator>AHack210</dc:creator>
      <dc:date>2024-03-21T19:52:57Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 9.12 how to remove an ACL line</title>
      <link>https://community.cisco.com/t5/network-security/asa-9-12-how-to-remove-an-acl-line/m-p/5047240#M1110239</link>
      <description>&lt;P&gt;Hi Aref,&lt;/P&gt;&lt;P&gt;Thanks for your response.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Typing the full "no access-list ACLNAME parameters" actually worked and the ACL line gets removed as expected. I thought I tried it and it failed but perhaps I made a typo then.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Still odd why the WORD option isn't appearing and also autofill is not working when something like this is tried:&lt;BR /&gt;asa(config)# no access-list ACLNAME ?&lt;BR /&gt;ERROR: % Unrecognized command&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Guess a bug dropped in somewhere between 9.0 and 9.12..&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;</description>
      <pubDate>Thu, 21 Mar 2024 22:39:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-9-12-how-to-remove-an-acl-line/m-p/5047240#M1110239</guid>
      <dc:creator>ivanDmi</dc:creator>
      <dc:date>2024-03-21T22:39:32Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 9.12 how to remove an ACL line</title>
      <link>https://community.cisco.com/t5/network-security/asa-9-12-how-to-remove-an-acl-line/m-p/5047242#M1110240</link>
      <description>&lt;P&gt;Hi MHM, thanks for your reply. "inactive" didnt make a difference and a reboot unfortunately isn't an option in this environment. However, as suggested in the below response, entering the full "no access-list ...." command blindly works.&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;</description>
      <pubDate>Thu, 21 Mar 2024 22:41:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-9-12-how-to-remove-an-acl-line/m-p/5047242#M1110240</guid>
      <dc:creator>ivanDmi</dc:creator>
      <dc:date>2024-03-21T22:41:58Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 9.12 how to remove an ACL line</title>
      <link>https://community.cisco.com/t5/network-security/asa-9-12-how-to-remove-an-acl-line/m-p/5047244#M1110241</link>
      <description>&lt;P&gt;I glad your issue is solved&amp;nbsp;&lt;/P&gt;
&lt;P&gt;And as you mentioned it can be cosmetic bug.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Have a nice day friend&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Thu, 21 Mar 2024 22:44:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-9-12-how-to-remove-an-acl-line/m-p/5047244#M1110241</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-03-21T22:44:06Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 9.12 how to remove an ACL line</title>
      <link>https://community.cisco.com/t5/network-security/asa-9-12-how-to-remove-an-acl-line/m-p/5047245#M1110242</link>
      <description>&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;P&gt;Hi AHack210, thanks for your reply. That I tried and ACLs are present and look completely normal.&lt;/P&gt;&lt;P&gt;Oddly enough,&amp;nbsp;entering the full "no access-list ...." command blindly works as expected though. Gonna have to settle for this.&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Thu, 21 Mar 2024 22:44:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-9-12-how-to-remove-an-acl-line/m-p/5047245#M1110242</guid>
      <dc:creator>ivanDmi</dc:creator>
      <dc:date>2024-03-21T22:44:16Z</dc:date>
    </item>
  </channel>
</rss>

